Authdog

Microsoft Entra ID

Last updated Oct 6, 2026
View as Markdown

Microsoft Entra ID (formerly Azure AD) connects to Authdog over OpenID Connect. Entra stays the system of record for your workforce; Authdog fronts your application and consumes the ID token.

Copy the redirect URL

In the Authdog console, select the project and environment, open Authentication > Providers, find Microsoft Entra ID, and click Enable. Copy the Redirect / Callback URL:

https://identity.authdog.com/api/v1/callback/<connectionId>

Each environment has its own connection id, so its own redirect URL.

Register the application in Entra

  1. In the Entra admin center, open Identity > Applications > App registrations and click New registration.
  2. Set a name, keep Accounts in this organizational directory only, and add a Web redirect URI with the Authdog callback URL.
  3. Under Certificates & secrets, create a client secret and copy its value — it is shown once.
  4. Copy the Application (client) ID from the Overview page.
  5. Note the OpenID Connect metadata document URL, e.g. https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration.

Configure Authdog

Field Value
Client ID Application (client) ID
Client secret The secret value from Certificates & secrets
Discovery URL The OpenID Connect metadata document URL (the /.well-known/openid-configuration suffix is optional)
Email domains Domains routed to this connection, e.g. acme.com

Save, then toggle the connection active.

Test the connection

  1. On the saved connection, click Test connection. Authdog validates the required fields, then fetches the discovery document and confirms it carries authorization_endpoint, token_endpoint, and jwks_uri. Failures come back with named codes — unreachable when the document cannot be fetched, missing_endpoint when it is the wrong document.
  2. Then run a real login: open the Login URL, complete the Entra prompt, and confirm the user appears under Users with an Entra identity linked.

Rotate the secret

Entra client secrets expire. When one does:

  1. Create a new secret under Certificates & secrets.
  2. Paste it into the connection's Client secret field and save.

No downtime: the old secret keeps working until Entra expires it. Secret rotations are recorded in the environment audit log.

Troubleshooting

Symptom Cause
unreachable fault on discovery Wrong tenant id in the discovery URL, or the app registration was deleted
missing_endpoint fault The URL points at a v1 endpoint or a non-OIDC document — use the v2.0 metadata URL
AADSTS700016 The client ID does not exist in this tenant
AADSTS50011 The redirect URI is not registered on the app registration
User looped back to sign-in Email domain not listed on the connection
Read To learn how to
Enterprise SSO Understand the SSO model and discovery
SCIM provisioning Sync Entra users and groups over SCIM
Okta Connect Okta over SAML instead

Learn more